Developer
News and Updates
Get Support
Sign in
Get Support
Sign in
DOCUMENTATION
Cloud
Data Center
Resources
Sign in
Sign in
DOCUMENTATION
Cloud
Data Center
Resources
Sign in
Last updated Sep 28, 2026

Apply for Atlassian Enterprise Certified

Forge cloud apps that meet the Atlassian Enterprise Certified (AEC) program requirements can apply for certification.

This guide explains how to prepare your app, run the pre-submission validation scan, resolve any issues, and submit your application.

Before you apply

Confirm that you have access

To access an AEC application, you must:

  • Be listed in the ticket's Partner Participants field of the application ticket.

If a team member needs access:

  1. Open your Marketplace Partner account.
  2. Go to Team and select Add team member.
  3. Add the team member and assign them the Security role.

Marketplace Partner account roles sync to the ticket once per day. After the sync adds the team member to Partner Participants, they can access the AEC Scorecard.

Add team member form with the Security role highlighted

Review the requirements

Review the current AEC requirements and validation methods. Make sure that your app meets the requirements before you start an application.

Prepare your evidence and documentation

Confirm that your app, operational processes, and trust center documentation are ready for validation.

Use the approved document naming conventions in the Required Documentation section. The validation scanner uses these conventions to identify documents in your trust center.

Complete this preparation before applying. If the pre-submission validation scan finds that your app does not meet the requirements, you won't be able to submit the application.

Prepare your app information

For each app that you submit, provide:

  • The app identifier or app key.
  • The vendor identifier.
  • A public trust center URL.
  • A security contact and phone number.

Submit an application

To create an AEC application:

  1. Open the AEC application form in the Developer Support portal. If you navigate from the portal, select Security programs, then Apply for the Atlassian Enterprise Certified Apps program.
  2. Enter your vendor ID, the app keys you want to include, and your trust center URL.
  3. Enter your security contact email and phone number for 24/5 security alerts monitoring.
  4. Select Send.
Developer Support portal form for applying to the Atlassian Enterprise Certified Apps Program

Include every app that you want reviewed when you create the ticket. There are options to add and remove apps, so this is flexible.

After you create the ticket, you can navigate to the AEC Scorecard and trigger a scan. The ticket receives a comment when the scan is complete.

Run the AEC Scorecard

Open AEC Scorecard from the app list in the top-right area of the application ticket.

AEC application ticket with the AEC Scorecard highlighted in the right sidebar

The scorecard:

  • Scans each submitted app separately or all together.
  • Displays the scanned build number and scan completion time.
  • Evaluates 25 active AEC requirements.
  • Shows Passed, Failed, Incomplete, Review required, and Error states.
  • Provides detected evidence and remediation instructions.
AEC Scorecard showing multiple submitted apps with individual rescan controls

A failed requirement means the scan completed and found an unmet requirement. It doesn't mean that the scan itself failed.

Review the results

Use the following scorecard views:

  • Needs attention shows requirements that require action.
  • All requirements shows the complete scorecard.

For a non-passing requirement, select Show remediation details to review:

AEC Scorecard showing scan details, Needs attention and All requirements tabs, and failed requirements

Publish any required app changes before requesting another scan. Keep in mind that it may take up to 24 hours for this new version to be available to the scorecard.

Request another scan

You can start a new assessment in either of these ways:

  • Select Request rescan beside an individual app identifier.
  • Select Rescan all apps from the application dashboard.
AEC Scorecard with the Rescan all apps and individual Request rescan controls highlighted

A rescan creates a new assessment; it doesn't resume the previous scan. Until a newly published version becomes available to the scanner, results can continue to reflect the previous build.

Trust center and AI policy review

Your public trust center must use a supported provider. See requirement 3.1 in the AEC program requirements for the current list.

Vanta and SafeBase trust centers are checked automatically. Trust centers hosted by another supported provider require manual review.

If your supported trust center requires manual review, you can submit the application after all automated checks unrelated to the trust center have passed. Atlassian reviews the trust center documentation, including the AI usage policy for requirement 5.1, during application review.

If your trust center provider isn't on the list, the trust center checks will fail and you will not be able to submit the

Request an exception

If you dispute a non-passing requirement, find the app's results in the AEC Scorecard and select Request exception.

In the request:

  1. Select every requirement that you want Atlassian to reconsider.
  2. Explain why each result should be reconsidered.
  3. Provide links or supporting evidence where possible.
AEC Scorecard exception form showing requirement selection, supporting evidence, and the Submit exception request button

The exception request and supporting evidence are shared with Atlassian for review.

Exception requests are intended for cases where the scanner:

  • Doesn't detect evidence that you have supplied.
  • Incorrectly reports that your app violates a requirement.

An exception request isn't a substitute for meeting a requirement. Requests based only on an unmet requirement will generally be rejected.

Approved exceptions count toward your scorecard result.

Handle scan failures

A requirement failure and a scan-processing failure are different:

  • A Failed requirement means that the scan completed but the app didn't meet that requirement.
  • Scan failed means that the scanner couldn't complete the assessment.

If the app shows Scan failed, you can request another scan or select Report scan failure in the scorecard app.

AEC Scorecard showing a failed scan and the Request rescan and Report scan failure actions

After you report the failure, the affected app displays Waiting for Atlassian. Atlassian reviewers receive the restricted technical error details.

Apply for review

The Apply to AEC button becomes available when:

  • Every submitted app either passes each automated check unrelated to the trust center or has an approved exception for each non-passing result.
  • The trust center uses a supported provider and is eligible for automated or manual review.
  • No app has an active scan-processing error.
Completed AEC Scorecard showing that all submitted apps meet the requirements and the Apply to AEC button is available

Select Apply to AEC to move the application to Under Review. Atlassian then validates the results.

If Atlassian needs more information or remediation, the team will use the ECOHELP ticket to explain the gap and discuss next steps.

After approval, Atlassian adds the AEC badge to the app's Marketplace listing.

Check scan notifications

When a scan completes, Atlassian adds a comment to the application ticket containing:

  • The app identifier.
  • The scanned build number.
  • Directions to open the AEC Scorecard.

Use this information to confirm that Atlassian assessed the app build that you intended to submit.

It can take up to 24 hours for a newly published app version to become available to the scanner.

Application ticket comment showing the assessed app identifier, scanned build, and direction to the AEC Scorecard

Frequently asked questions

How do I add or remove an app from my application?

To add an app after creating an AEC application, create a separate application ticket for that app.

You don't need to formally remove an app that you no longer want to submit. In the AEC Scorecard, choose which apps you want to scan and submit. Leave an app unselected if you don't want it included.

When should I request an exception?

Request an exception when you believe the scanner has missed valid evidence or incorrectly marked a requirement as unmet. In the AEC Scorecard, select Request exception beside the app's results, choose each result you want reconsidered, and provide an explanation with supporting links or evidence.

Don't request an exception when your app simply doesn't meet the requirement. Make the required changes, publish a new app version if necessary, and request another scan.

A requirement didn't pass, but I supplied the required information. What should I do?

For a trust center check, confirm that the document name follows the required naming conventions.

For other checks:

  1. Review the latest explanation in the AEC Scorecard.
  2. If you recently released a new app version, wait up to 24 hours and rescan.
  3. If you believe the scanner result is incorrect, submit an exception request from the scorecard.

How are requirement violations managed after certification?

Atlassian scans certified apps daily for the requirements that were checked during onboarding. The checks may change over time.

If Atlassian detects a violation, you will receive an ECOHELP ticket that identifies the affected app and requirement. You have 30 days from detection to remediate the violation before Atlassian takes enforcement action.

What if I don't have a current penetration test report?

Atlassian offers a managed penetration testing program in collaboration with Bugcrowd. See the Marketplace Penetration Testing Program to get started.

What if SOC 2 Type II or ISO 27001 certification is too expensive for my company?

Atlassian offers eligible Marketplace Partners a subsidy for a one-year subscription to Vanta's core offering. The offering includes:

  • Support for completing either SOC 2 or ISO 27001.
  • A Vanta-hosted trust center that continuously reports control completion.

See the Partner Compliance Program Quick Reference Guide for details.

Rate this page: